Patentable/Patents/US-9602291
US-9602291

Secure connection certificate verification

PublishedMarch 21, 2017
Assigneenot available in USPTO data we have
Inventorsnot available in USPTO data we have
Technical Abstract

One or more computer processors identify a first certificate that is used to establish a secure Internet connection. One or more computer processors identify a stored second certificate that shares at least one attribute with the first certificate. One or more computer processors determine a policy action based, at least in part, on a result of a comparison between an attribute of the first certificate and an attribute of the second certificate.

Patent Claims
8 claims

Legal claims defining the scope of protection. Each claim is shown in both the original legal language and a plain English translation.

Claim 1

Original Legal Text

1. A method for determining a policy action for a connection in which certificates are utilized in a secure network connection, the method comprising: identifying, by one or more computer processors, a first certificate that is used to establish a secure Internet connection; identifying, by one or more computer processors, a stored second certificate that shares at least one attribute with the first certificate, wherein identifying a stored second certificate includes comparing one or more attributes of the first certificate with one or more attributes from each stored certificate from a plurality of stored certificates; and determining, by one or more computer processors, a policy action based, at least in part, on a result of a comparison between an attribute of the first certificate and an attribute of the stored second certificate.

Plain English Translation

A method for managing secure network connections using certificates compares a certificate from the current connection with stored certificates to determine a policy action. The system identifies a certificate used to establish a secure internet connection (like HTTPS). It then searches a database of stored certificates, comparing attributes of the current certificate to attributes of each stored certificate. Based on the comparison, a policy action is determined. This allows the system to react to potentially malicious or untrusted certificates based on comparison results.

Claim 2

Original Legal Text

2. The method of claim 1 , further comprising: executing, by one or more computer processors, the determined policy action on a client computing device.

Plain English Translation

The method of managing secure network connections includes executing a policy action (from the comparison of a certificate used to establish a secure internet connection and a stored second certificate that shares at least one attribute with the first certificate) on a client computing device. This allows the system to actively respond to certificate verification results, e.g., blocking a connection or displaying a warning message directly on the user's machine.

Claim 3

Original Legal Text

3. The method of claim 1 , wherein identifying a first certificate that is used to establish a secure Internet connection comprises: identifying, by one or more computer processors, a certificate that is utilized to establish a secure Internet connection via deep-packet inspection; and storing, by one or more computer processors, the identified certificate in a storage device.

Plain English Translation

The method of managing secure network connections specifies how the current connection's certificate is identified: It uses deep-packet inspection to extract the certificate used to establish a secure Internet connection. The identified certificate is then stored in a storage device. This enables the system to analyze the secure connection's certificate and use it for comparison against stored certificates.

Claim 4

Original Legal Text

4. The method of claim 1 , wherein the secure Internet connection is one or both of a cryptographic protocol, or an encryption protocol, wherein the one or both of the cryptographic protocol, or the encryption protocol, is one or more of a secure socket layer connection, or a transport layer security.

Plain English Translation

In the method of managing secure network connections, the secure Internet connection is a cryptographic or encryption protocol such as Secure Socket Layer (SSL) or Transport Layer Security (TLS). The system therefore analyzes SSL or TLS connections to determine a policy action for a connection in which certificates are utilized in the secure network connection.

Claim 5

Original Legal Text

5. The method of claim 1 , wherein the stored second certificate is located in a database that is at least in part managed by an in-line computing device.

Plain English Translation

In the method of managing secure network connections, the stored certificates used for comparison are located in a database. This database is at least partly managed by an in-line computing device. This means the certificate database can be updated and maintained by a network appliance that actively monitors and manages network traffic.

Claim 6

Original Legal Text

6. The method of claim 1 , wherein determining the policy action occurs after the secure Internet connection has been established.

Plain English Translation

In the method of managing secure network connections, the policy action based on the certificate comparison is determined *after* the secure Internet connection has already been established. This implies the system allows the connection initially but monitors and evaluates the certificate in the background to decide on a subsequent policy adjustment.

Claim 7

Original Legal Text

7. The method of claim 1 , wherein determining, by one or more computer processors, a policy action based, at least in part, on a result of a comparison between an attribute of the first certificate and an attribute of the stored second certificate comprises: determining, by one or more computer processors, that a type of attribute of the first certificate includes content that is different than a content of a same type of attribute of the second certificate; and executing, by one or more computer processors, the policy action based, at least in part, on a difference in the content of the type of attribute of the first certificate and the content of the same type of attribute of the second certificate.

Plain English Translation

The method of managing secure network connections bases its policy action on a difference between the current connection's certificate and a stored certificate. It determines that a specific attribute of the current certificate has different content than the same attribute in the stored certificate. For example, if the "common name" field differs. Then, the policy action is executed based on this difference. This allows for fine-grained control based on specific certificate attributes.

Claim 8

Original Legal Text

8. The method of claim 5 , wherein the stored second certificate was received during the establishment of a previous secure Internet connection.

Plain English Translation

In the method of managing secure network connections where the stored certificates reside in a database managed by an in-line computing device, the stored certificates were previously received during the establishment of prior secure internet connections. This indicates that the system builds its database of trusted or suspicious certificates by observing past connections and storing the associated certificates.

Classification Codes (CPC)

Cooperative Patent Classification codes for this invention. Click any code to explore related patents in that topic.

Patent Metadata

Filing Date

June 2, 2015

Publication Date

March 21, 2017

Want to explore more patents?

Browse 5M+ US patents with plain-English claim translations and AI-generated analysis.

Citation & reuse

Analysis on this page is generated by Patentable — an AI-powered patent intelligence platform. AI-generated summaries, explanations, FAQs, and analysis may be reused with attribution and a visible link back to the canonical URL below. Patent abstracts and claims are USPTO public domain.

Cite as: Patentable. “Secure connection certificate verification” (US-9602291). https://patentable.app/patents/US-9602291

© 2026 Nomic Interactive Technology LLC. Machine-readable context available at /api/llm-context/US-9602291. See llms.txt for full attribution policy.